
Core services
DAST Configuration and Application Onboarding
DAST Audit Readiness
Authenticated Scan Setup
Scan Profiles Setup

Advanced services
WAS API Automation
Risk-Based Reporting and Dashboards
AppSec Program Guidance
DAST Maturation, Automation and Optimization
We’ll create a tiered structure to accommodate short-term needs and long-term partnerships.
Tier 1:
DAST Audit Readiness Package
Target: Compliance-driven orgs who need to “pass the audit”
- 1-time scan configuration or review
- Up to 5 web applications
- Authentication setup (cookies, headers, tokens)
- Scan tuning to reduce false positives
- Executive + Technical report package
- 60-minute readout call
(Pricing scales slightly based on scan complexity and number of apps)
Tier 2:
DAST Optimization & Automation Engagement
Target: Teams who want to operationalize DAST long-term
- Everything in Tier 1, plus:
- WAS tagging and asset organization
- Integration with CI/CD (GitHub, Jenkins, GitLab, etc.)
- Scan profile automation + scheduling
- Ticketing system integration (e.g., Jira, ServiceNow)
- Alert tuning + risk-prioritized dashboards
- Monthly vulnerability review calls
Ongoing: $1,500 – $3,000/month (depends on volume + complexity)
Tier 3:
Fractional AppSec Program Support (Retainer)
Target: Orgs that want a part-time AppSec lead on call
- Unlimited WAS advisory
- Coordination with dev teams to close the loop
- Prioritization of critical vulns and SLA tracking
- Compliance check-ins and roadmap alignment
- Optional monthly security workshop or training
(Ideal for companies without full AppSec leadership)